Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Getting rid of annoying dialing sound  (Read 15264 times)

0 Members and 1 Guest are viewing this topic.

Broni


    Mastermind
  • Kraków my love :)
  • Thanked: 614
    • Computer Help Forum
  • Computer: Specs
  • Experience: Experienced
  • OS: Windows 8
Re: Getting rid of annoying dialing sound
« Reply #15 on: October 08, 2008, 08:10:49 PM »
Oh, that was 1st part only...
I'll PM you with my email address. You can send it there.

dianeliz

    Topic Starter


    Rookie

    Re: Getting rid of annoying dialing sound
    « Reply #16 on: October 09, 2008, 04:56:18 PM »
    Hi again!  I do not have a phone jack at all.  In fact, area 2 is all "boarded" up; there's nothing there at all, though I gather I could complicate my computer in the future if I should choose to.  :-)

    patio

    • Moderator


    • Genius
    • Maud' Dib
    • Thanked: 1725
      • Yes
    • Experience: Beginner
    • OS: Windows 7
    Re: Getting rid of annoying dialing sound
    « Reply #17 on: October 09, 2008, 05:07:37 PM »
    Hi again!  I do not have a phone jack at all.  In fact, area 2 is all "boarded" up; there's nothing there at all, though I gather I could complicate my computer in the future if I should choose to.  :-)

    Yes...that's exactly what Area2 is for.... ;D          ;D

    BTW Welcome Aboard and we'll get you fixed up.
    " Anyone who goes to a psychiatrist should have his head examined. "

    Broni


      Mastermind
    • Kraków my love :)
    • Thanked: 614
      • Computer Help Forum
    • Computer: Specs
    • Experience: Experienced
    • OS: Windows 8
    Re: Getting rid of annoying dialing sound
    « Reply #18 on: October 09, 2008, 05:15:17 PM »
    I received your GMER log. I'll check it out in a few.

    Broni


      Mastermind
    • Kraków my love :)
    • Thanked: 614
      • Computer Help Forum
    • Computer: Specs
    • Experience: Experienced
    • OS: Windows 8
    Re: Getting rid of annoying dialing sound
    « Reply #19 on: October 09, 2008, 05:22:22 PM »
    Unfortunately (fortunately?), nothing suspicious in GMER log.
    We must keep looking for some other solutions.
    Possible to try another pair of speakers?

    dianeliz

      Topic Starter


      Rookie

      Re: Getting rid of annoying dialing sound
      « Reply #20 on: October 09, 2008, 05:43:32 PM »
      Interesting thought.  I just 'borrowed' the speakers from my husband's system, but I still get the dialing sound. 

      You know, I don't know if this will help, but I don't think I ever described the dialing sound.  If you're old enough to remember phones with rotary dials, that's what it sounds like, the sound the phone would make as you dialed each number and the dial rotated back to the starting position.

      Another thought.  Could there be some setting somewhere on my machine that makes some part of the machine think there's a dial-up modem which it keeps trying to activate?  I don't know what or where it could be, but perhaps this perhaps triggers an idea?

      Broni


        Mastermind
      • Kraków my love :)
      • Thanked: 614
        • Computer Help Forum
      • Computer: Specs
      • Experience: Experienced
      • OS: Windows 8
      Re: Getting rid of annoying dialing sound
      « Reply #21 on: October 09, 2008, 06:00:38 PM »
      Yes, I'm old enough :D
      Check in Device Manager, what is listed under "Modems".
      Also, see, if same sound can be heard in Safe Mode.

      dianeliz

        Topic Starter


        Rookie

        Re: Getting rid of annoying dialing sound
        « Reply #22 on: October 18, 2008, 07:29:09 PM »
        Hi again!  Sorry for the long delay.  I do appreciate your patience.

        There is no modem listed at all under device manager.

        There is no dialing sound in safe mode.  That got me all enthused, so I went into msconfig and one-by-one started removing programs from my startup.  Unfortunately, even when I got down to only the system programs, I was still getting the dialing sound.  :-(  So, I put them all back.  At least we know it's some program, not a hardware glitch, right?  What else, besides the startup programs, doesn't 'go' in safe mode?

        Thanks!
        Diane

        Broni


          Mastermind
        • Kraków my love :)
        • Thanked: 614
          • Computer Help Forum
        • Computer: Specs
        • Experience: Experienced
        • OS: Windows 8
        Re: Getting rid of annoying dialing sound
        « Reply #23 on: October 18, 2008, 07:32:19 PM »
        Download HijackThis:
        http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
        Click on Download HijackThis Installer
        Post HijackTHis log.

        I want to see, what's running there.

        dianeliz

          Topic Starter


          Rookie

          Re: Getting rid of annoying dialing sound
          « Reply #24 on: October 18, 2008, 07:42:04 PM »
          That was easy since I did this before.  :-)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 6:41:10 PM, on 18-Oct-08
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16735)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\PCSecurityShield\The Shield Deluxe 2008\avp.exe
          C:\WINDOWS\system32\VTtrayp.exe
          C:\WINDOWS\system32\VTTimer.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
          C:\WINDOWS\system32\DrvMon.exe
          C:\WINDOWS\sabserv.exe
          C:\Program Files\Alarm95\Alarm95.exe
          C:\Program Files\MemTurbo30\MemTurbo.exe
          C:\Program Files\OpenOffice.org 2.2\program\soffice.exe
          C:\Program Files\OpenOffice.org 2.2\program\soffice.BIN
          C:\Program Files\PCSecurityShield\The Shield Deluxe 2008\avp.exe
          C:\WINDOWS\system32\CfgSrvc.exe
          C:\WINDOWS\system32\cisvc.exe
          C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
          C:\WINDOWS\system32\CfgSrvc.exe
          C:\WINDOWS\SDMan.EXE
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\UPSMON\UPSMON_Service.Exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\WINDOWS\system32\cidaemon.exe
          C:\Program Files\Java\jre1.5.0_11\bin\javaw.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\WINDOWS\system32\spider.exe
          C:\WINDOWS\system32\rundll32.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://start.earthlink.net/AL/Search
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://24.248.216.205/exchange/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us.mcafee.com/root/landingpages/cd.asp?affid=307&lpname=vso&cid=8152&appurl=http://us.mcafee.com/apps/AppCommon/updreg.asp?app=http://us.mcafee.com/apps/vso/en-us/redir.asp?affid=307&installtype=force&lpname=vso&systempopup=true (obfuscated)
          O1 - Hosts: 127.0.0.34 ofep34.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.23 ofep23.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.36 fos.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.8 ofep08.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.21 ofep21.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.32 ofep32.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.44 access.certd.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.36 frt.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.28 ofep28.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.30 ofep30.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.6 ofep06.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.41 access.tstsa.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.26 ofep26.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.4 ofep04.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.35 ofep35.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.24 ofep24.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.37 lb1.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.39 tsts.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.39 access.tsts.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.33 ofep33.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.9 ofep09.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.22 ofep22.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.29 ofep29.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.40 cert.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.31 ofep31.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.7 ofep07.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.40 access.cert.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.20 ofep20.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.43 access.certc.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.42 access.tstsb.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.27 ofep27.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.5 ofep05.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.36 decs.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.25 ofep25.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.38 lb2.sabre.com # Nortel SSL-VPN
          O1 - Hosts: 127.0.0.3 ofep03.sabre.com # Nortel SSL-VPN
          O2 - BHO: EarthLink BHO Guard - {00000000-0000-0000-0000-000000000002} - C:\Program Files\EarthLink TotalAccess\Toolbar\EScamBlk.dll
          O2 - BHO: EarthLink ScamBlocker V3 - {15F4D456-5BAA-4076-8486-EECB38CD3E57} - C:\Program Files\EarthLink TotalAccess\Toolbar\EScamBlk.dll
          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
          O2 - BHO: EarthLink PopUp Blocker V2 - {512ACF1B-64D9-4928-B382-A80556F28DB4} - C:\Program Files\EarthLink TotalAccess\Toolbar\ElnkPub.dll
          O2 - BHO: IE_PopupBlocker Class - {656EC4B7-072B-4698-B504-2A414C1F0037} - C:\Program Files\EarthLink TotalAccess\Accelerator\prpl_IePopupBlocker.dll
          O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
          O2 - BHO: Earthlink Protection BHO - {9579D574-D4D8-4335-9560-FE8641A013BD} - C:\Program Files\EarthLink TotalAccess\Toolbar\ProtctIE.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
          O2 - BHO: Uninstall Legacy Earthlink Toolbar - {E713904C-DF05-4C79-BBAD-02DB923253BE} - C:\Program Files\EarthLink TotalAccess\Toolbar\uninsttb.dll
          O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
          O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
          O3 - Toolbar: EarthLink Toolbar - {C7768536-96F8-4001-B1A2-90EE21279187} - C:\Program Files\EarthLink TotalAccess\Toolbar\Toolbar.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
          O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
          O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
          O4 - HKLM\..\Run: [AVP] "C:\Program Files\PCSecurityShield\The Shield Deluxe 2008\avp.exe"
          O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
          O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
          O4 - HKLM\..\Run: [VrSchedule] C:\Program Files\PCSecurityShield\ShieldAntivirus\Vrres.exe
          O4 - HKLM\..\Run: [Vrmon] C:\Program Files\PCSecurityShield\ShieldAntivirus\vrmonnt.exe Main
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
          O4 - HKCU\..\Run: [DrvMon.exe] C:\WINDOWS\system32\DrvMon.exe
          O4 - Startup: Alarm 95.lnk = C:\Program Files\Alarm95\Alarm95.exe
          O4 - Startup: CleanupNortelVPN.bat
          O4 - Startup: MemTurbo.lnk = C:\Program Files\MemTurbo30\MemTurbo.exe
          O4 - Startup: Microsoft Office Fast Start.lnk = C:\MSOffice\Office\FASTBOOT.EXE
          O4 - Startup: Microsoft Office Find Fast Indexer.lnk = C:\MSOffice\Office\FINDFAST.EXE
          O4 - Startup: OpenOffice.org 2.2.lnk = C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe
          O4 - Global Startup: Sabre Server.lnk = C:\WINDOWS\sabserv.exe
          O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
          O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
          O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
          O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
          O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
          O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
          O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\PCSecurityShield\The Shield Deluxe 2008\scieplugin.dll
          O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
          O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
          O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
          O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
          O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
          O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
          O15 - Trusted Zone: *.agentware.net
          O15 - Trusted Zone: *.jacquielawson.com
          O15 - Trusted Zone: *.sabre.com
          O15 - Trusted Zone: *.vacationstudio.net
          O15 - Trusted Zone: *.virtuallythere.com
          O16 - DPF: {03A89EFD-E023-7700-A22D-45F77558EB4C} (ILINCInstall77 Class) - http://learnlinc.sabre.com/download/ilinci77.dll
          O16 - DPF: {2D36AF92-04D3-11D8-B719-0000865F231B} (TMinReq Class) - https://my.sabre.com/jars/TMinReqX.dll
          O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://tnz.webex.com/client/T25L/training/ieatgpc.cab
          O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
          O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll
          O23 - Service: The Shield Deluxe 2008 (AVP) - PCSecurityShield - C:\Program Files\PCSecurityShield\The Shield Deluxe 2008\avp.exe
          O23 - Service: Config Service Helper (CfgSrvc) - Unknown owner - C:\WINDOWS\system32\CfgSrvc.exe
          O23 - Service: EarthLink Monitor Service (EarthLinkMonitor) - Boingo Wireless, Inc. - C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
          O23 - Service: EarthLink Firewall Process Path Service (ElnkFWPPService) - Unknown owner - C:\PROGRA~1\EARTHL~1\PROTEC~1\EFWPPS~1.EXE (file missing)
          O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: HSSP Configuration Module (HsspConfig) - Unknown owner - C:\WINDOWS\system32\CfgSrvc.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: Sabre Device Manager (SDMan) - Unknown owner - C:\WINDOWS\SDMan.EXE
          O23 - Service: UPSMONService - Unknown owner - C:\Program Files\UPSMON\UPSMON_Service.Exe

          --
          End of file - 12948 bytes

          Broni


            Mastermind
          • Kraków my love :)
          • Thanked: 614
            • Computer Help Forum
          • Computer: Specs
          • Experience: Experienced
          • OS: Windows 8
          Re: Getting rid of annoying dialing sound
          « Reply #25 on: October 18, 2008, 07:48:46 PM »
          Did you modify your "hosts" file on purpose?
          I'd like to see also, HJT log from Safe Mode, so I can compare.

          I'm leaving for the movies right now, so I'll take a look at your reply, and at your logs later tonight, or tomorrow morning.

          dianeliz

            Topic Starter


            Rookie

            Re: Getting rid of annoying dialing sound
            « Reply #26 on: October 18, 2008, 08:29:09 PM »
            I hope you enjoyed the movie!  My husband and I watch movies on Saturday night too. 

            What is a "hosts" file?

            Here is the safe mode log:
            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 7:23:04 PM, on 18-Oct-08
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16735)
            Boot mode: Safe mode

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://start.earthlink.net/AL/Search
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://24.248.216.205/exchange/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
            R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us.mcafee.com/root/landingpages/cd.asp?affid=307&lpname=vso&cid=8152&appurl=http://us.mcafee.com/apps/AppCommon/updreg.asp?app=http://us.mcafee.com/apps/vso/en-us/redir.asp?affid=307&installtype=force&lpname=vso&systempopup=true (obfuscated)
            O1 - Hosts: 127.0.0.34 ofep34.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.23 ofep23.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.36 fos.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.8 ofep08.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.21 ofep21.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.32 ofep32.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.44 access.certd.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.36 frt.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.28 ofep28.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.30 ofep30.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.6 ofep06.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.41 access.tstsa.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.26 ofep26.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.4 ofep04.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.35 ofep35.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.24 ofep24.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.37 lb1.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.39 tsts.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.39 access.tsts.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.33 ofep33.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.9 ofep09.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.22 ofep22.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.29 ofep29.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.40 cert.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.31 ofep31.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.7 ofep07.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.40 access.cert.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.20 ofep20.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.43 access.certc.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.42 access.tstsb.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.27 ofep27.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.5 ofep05.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.36 decs.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.25 ofep25.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.38 lb2.sabre.com # Nortel SSL-VPN
            O1 - Hosts: 127.0.0.3 ofep03.sabre.com # Nortel SSL-VPN
            O2 - BHO: EarthLink BHO Guard - {00000000-0000-0000-0000-000000000002} - C:\Program Files\EarthLink TotalAccess\Toolbar\EScamBlk.dll
            O2 - BHO: EarthLink ScamBlocker V3 - {15F4D456-5BAA-4076-8486-EECB38CD3E57} - C:\Program Files\EarthLink TotalAccess\Toolbar\EScamBlk.dll
            O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
            O2 - BHO: EarthLink PopUp Blocker V2 - {512ACF1B-64D9-4928-B382-A80556F28DB4} - C:\Program Files\EarthLink TotalAccess\Toolbar\ElnkPub.dll
            O2 - BHO: IE_PopupBlocker Class - {656EC4B7-072B-4698-B504-2A414C1F0037} - C:\Program Files\EarthLink TotalAccess\Accelerator\prpl_IePopupBlocker.dll
            O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
            O2 - BHO: Earthlink Protection BHO - {9579D574-D4D8-4335-9560-FE8641A013BD} - C:\Program Files\EarthLink TotalAccess\Toolbar\ProtctIE.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
            O2 - BHO: Uninstall Legacy Earthlink Toolbar - {E713904C-DF05-4C79-BBAD-02DB923253BE} - C:\Program Files\EarthLink TotalAccess\Toolbar\uninsttb.dll
            O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
            O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
            O3 - Toolbar: EarthLink Toolbar - {C7768536-96F8-4001-B1A2-90EE21279187} - C:\Program Files\EarthLink TotalAccess\Toolbar\Toolbar.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
            O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
            O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
            O4 - HKLM\..\Run: [AVP] "C:\Program Files\PCSecurityShield\The Shield Deluxe 2008\avp.exe"
            O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
            O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
            O4 - HKLM\..\Run: [VrSchedule] C:\Program Files\PCSecurityShield\ShieldAntivirus\Vrres.exe
            O4 - HKLM\..\Run: [Vrmon] C:\Program Files\PCSecurityShield\ShieldAntivirus\vrmonnt.exe Main
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
            O4 - HKCU\..\Run: [DrvMon.exe] C:\WINDOWS\system32\DrvMon.exe
            O4 - Startup: Alarm 95.lnk = C:\Program Files\Alarm95\Alarm95.exe
            O4 - Startup: CleanupNortelVPN.bat
            O4 - Startup: MemTurbo.lnk = C:\Program Files\MemTurbo30\MemTurbo.exe
            O4 - Startup: Microsoft Office Fast Start.lnk = C:\MSOffice\Office\FASTBOOT.EXE
            O4 - Startup: Microsoft Office Find Fast Indexer.lnk = C:\MSOffice\Office\FINDFAST.EXE
            O4 - Startup: OpenOffice.org 2.2.lnk = C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe
            O4 - Global Startup: Sabre Server.lnk = C:\WINDOWS\sabserv.exe
            O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
            O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
            O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
            O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
            O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
            O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\PCSecurityShield\The Shield Deluxe 2008\scieplugin.dll
            O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
            O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
            O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
            O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
            O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
            O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
            O15 - Trusted Zone: *.agentware.net
            O15 - Trusted Zone: *.jacquielawson.com
            O15 - Trusted Zone: *.sabre.com
            O15 - Trusted Zone: *.vacationstudio.net
            O15 - Trusted Zone: *.virtuallythere.com
            O16 - DPF: {03A89EFD-E023-7700-A22D-45F77558EB4C} (ILINCInstall77 Class) - http://learnlinc.sabre.com/download/ilinci77.dll
            O16 - DPF: {2D36AF92-04D3-11D8-B719-0000865F231B} (TMinReq Class) - https://my.sabre.com/jars/TMinReqX.dll
            O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://tnz.webex.com/client/T25L/training/ieatgpc.cab
            O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
            O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll
            O23 - Service: The Shield Deluxe 2008 (AVP) - PCSecurityShield - C:\Program Files\PCSecurityShield\The Shield Deluxe 2008\avp.exe
            O23 - Service: Config Service Helper (CfgSrvc) - Unknown owner - C:\WINDOWS\system32\CfgSrvc.exe
            O23 - Service: EarthLink Monitor Service (EarthLinkMonitor) - Boingo Wireless, Inc. - C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
            O23 - Service: EarthLink Firewall Process Path Service (ElnkFWPPService) - Unknown owner - C:\PROGRA~1\EARTHL~1\PROTEC~1\EFWPPS~1.EXE (file missing)
            O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: HSSP Configuration Module (HsspConfig) - Unknown owner - C:\WINDOWS\system32\CfgSrvc.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: Sabre Device Manager (SDMan) - Unknown owner - C:\WINDOWS\SDMan.EXE
            O23 - Service: UPSMONService - Unknown owner - C:\Program Files\UPSMON\UPSMON_Service.Exe

            --
            End of file - 11767 bytes

            Aegis



              Expert

              Thanked: 67
              • Yes
              • Yes
              • Brian's Mess Of A Web Page
            • Experience: Experienced
            • OS: Windows 10
            Re: Getting rid of annoying dialing sound
            « Reply #27 on: October 18, 2008, 10:23:59 PM »
            Quote
            You know, I don't know if this will help, but I don't think I ever described the dialing sound.  If you're old enough to remember phones with rotary dials, that's what it sounds like, the sound the phone would make as you dialed each number and the dial rotated back to the starting position.

            Yes, that's called dial pulse.  Makes me wonder if the modem is set to call out via dial pulse instead of touch-tone.  Back in the day, there were Hayes modem compatible settings to control such things.  I wonder if there are settings via the modem's software?


            "For you, a thousand times over." - "The Kite Runner"

            Broni


              Mastermind
            • Kraków my love :)
            • Thanked: 614
              • Computer Help Forum
            • Computer: Specs
            • Experience: Experienced
            • OS: Windows 8
            Re: Getting rid of annoying dialing sound
            « Reply #28 on: October 19, 2008, 11:31:58 AM »
            Quote
            What is a "hosts" file?
            Since you don't know, most likely, you didn't modify it.

            In that case...
            Download HostsXpert ( http://www.majorgeeks.com/Hoster_d4626.html ) and then follow the steps below:

                * Unzip HostsXpert.zip
                * It will create a folder named HostsXpert in whatever folder you extract it to.
                * Run HostsXpert.exe by double clicking on it.
                * click Restore MS Hosts File and then click OK.
                * Click the X to exit the program

            Restart computer.
            1. Post fresh HJT log from Normal Mode.
            2. Post fresh HJT log from Safe Mode.
            3. Post fresh HJT log from Safe Mode with Networking. While here, see if you have dialing sound in Safe Mode with Networking.

            dianeliz

              Topic Starter


              Rookie

              Re: Getting rid of annoying dialing sound
              « Reply #29 on: October 20, 2008, 12:22:24 PM »
              Not on purpose, anyway.  :-)

              There is no dialing sound in safe mode with networking either.

              I think I'll try attaching the 3 logs...

              [Saving space - attachment deleted by admin]